Cisco ASR1002-10G-VPN/K9 Software Guide - Page 281

allow, allow interruptible, Ctrl-C, Ctrl-Shift-6, none disconnect, ip ssh, rsa keypair-name

Page 281 highlights

Chapter 8 Console Port, Telnet, and SSH Handling Configuring Persistent SSH Step 4 Command or Action connection wait [allow {interruptible}| none {disconnect}] Example: Router(config-tmap)# connection wait allow interruptible Purpose Specifies how a persistent SSH connection will be handled using this transport map: • allow-The SSH connection waits for the vty line to become available, and exits the router if interrupted. • allow interruptible-The SSH connection waits for the vty line to become available, and also allows users to enter diagnostic mode by interrupting a SSH connection waiting for the vty line to become available. This is the default setting. Note Users can interrupt a waiting connection by entering Ctrl-C or Ctrl-Shift-6. Step 5 Step 6 Step 7 • none-The SSH connection immediately enters diagnostic mode. • none disconnect-The SSH connection does not wait for the vty line from IOS and does not enter diagnostic mode, so all SSH connections are rejected if no vty line is immediately available. rsa keypair-name rsa-keypair-name Names the RSA keypair to be used for persistent SSH connections. Example: Router(config-tmap)# rsa keypair-name sshkeys For persistent SSH connections, the RSA keypair name must be defined using this command in transport map configuration mode. The RSA keypair definitions defined elsewhere on the router, such as through the use of the ip ssh rsa keypair-name command, do not apply to persistent SSH connections. No rsa-keypair-name is defined by default. authentication-retries number-of-retries (Optional) Specifies the number of authentication retries before dropping the connection. Example: The default number-of-retries is 3. Router(config-tmap)# authentication-retries 4 banner [diagnostic | wait] banner-message Example: Router(config-tmap)# banner diagnostic X Enter TEXT message. End with the character 'X'. --Welcome to Diagnostic Mode-X Router(config-tmap)# (Optional) Creates a banner message that will be seen by users entering diagnostic mode or waiting for the vty line as a result of the persistent SSH configuration. • diagnostic-Creates a banner message seen by users directed into diagnostic mode as a result of the persistent SSH configuration. • wait-Creates a banner message seen by users waiting for the vty line to become active. • banner-message-The banner message, which begins and ends with the same delimiting character. OL-16506-10 Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide 8-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378

8-9
Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide
OL-16506-10
Chapter 8
Console Port, Telnet, and SSH Handling
Configuring Persistent SSH
Step 4
connection wait
[
allow
{
interruptible
}|
none
{
disconnect
}]
Example:
Router(config-tmap)#
connection wait allow
interruptible
Specifies how a persistent SSH connection will be handled
using this transport map:
allow
—The SSH connection waits for the vty line to
become available, and exits the router if interrupted.
allow interruptible
—The SSH connection waits for
the vty line to become available, and also allows users
to enter diagnostic mode by interrupting a SSH
connection waiting for the vty line to become available.
This is the default setting.
Note
Users can interrupt a waiting connection by
entering
Ctrl-C
or
Ctrl-Shift-6
.
none
—The SSH connection immediately enters
diagnostic mode.
none disconnect
—The SSH connection does not wait
for the vty line from IOS and does not enter diagnostic
mode, so all SSH connections are rejected if no vty line
is immediately available.
Step 5
rsa keypair-name
rsa-keypair-name
Example:
Router(config-tmap)#
rsa keypair-name sshkeys
Names the RSA keypair to be used for persistent SSH
connections.
For persistent SSH connections, the RSA keypair name
must be defined using this command in transport map
configuration mode. The RSA keypair definitions defined
elsewhere on the router, such as through the use of the
ip ssh
rsa keypair-name
command, do not apply to persistent
SSH connections.
No
rsa-keypair-name
is defined by default.
Step 6
authentication-retries
number-of-retries
Example:
Router(config-tmap)#
authentication-retries 4
(Optional) Specifies the number of authentication retries
before dropping the connection.
The default
number-of-retries
is 3.
Step 7
banner
[
diagnostic
|
wait
]
banner-message
Example:
Router(config-tmap)#
banner diagnostic X
Enter TEXT message
.
End with the character
'X'.
--Welcome to Diagnostic Mode--
X
Router(config-tmap)#
(Optional) Creates a banner message that will be seen by
users entering diagnostic mode or waiting for the vty line as
a result of the persistent SSH configuration.
diagnostic
—Creates a banner message seen by users
directed into diagnostic mode as a result of the
persistent SSH configuration.
wait
—Creates a banner message seen by users waiting
for the vty line to become active.
banner-message
—The banner message, which begins
and ends with the same delimiting character.
Command or Action
Purpose